OpenSSF/OSV advisory MAL-2026-13541 confirms this npm version as malicious. This is an import-time, unconsented remote binary loader and executor, not package-aligned documentation functionality. The lack of lifecycle scripts does not mitigate the reachable runtime execution path.
A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_init.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkgA package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
_init.jsView on unpkg · L2Source file is highly similar to a previously finalized malicious package; route for source-aware review.
lib/telemetry.jsView on unpkg